Career listings

Consultant

Due to continued expansion, we’re looking for a Consultant to join the Cyberis Reply team. As part of our close-knit consultancy practice, you will work closely with clients to understand their business challenges, provide expert advice, and deliver high-quality cybersecurity and information security services. You will support a range of projects, from security assessments and risk management activities to compliance, governance, and cyber resilience initiatives, helping clients strengthen their security posture and achieve their business objectives.

Our team is dynamic, innovative and dedicated to making a difference to our clients’ security efforts. We recognise and reward our employees for exceptional results. We offer flexible work options when available and emphasise the importance of work-life balance.

Our office is in Tewkesbury, Gloucestershire, however opportunities to be home-based are available, with travel to clients sites.  

Duties 

As a Consultant you are expected to deliver penetration testing and information security consultancy as part of the Consultancy Team. The role aligns within the Cyberis Reply Role and Career Framework, based on experience and capability. The following duties will form the foundation of your role:  

  • Delivering high-quality penetration testing and information security consultancy in line with agreed scopes, timescales and budgets. 
  • Independently delivering standard assignments and, with experience, leading well-defined engagements or complex phases of work. 
  • Participating in pre-engagement discussions, scoping, client updates and debrief calls. 
  • Maintaining clear and professional communication with clients, colleagues and other involved parties. 
  • Building trusted client relationships and communicating findings, risk and remediation clearly. 
  • Managing workload, utilisation and scope responsibly, raising delivery risks or blockers early. 
  • Producing accurate, client-ready technical reports in line with Cyberis Reply standards. 
  • Maintaining and broadening technical capability, qualifications, clearances and CPD. 
  • Supporting the wider team and coordinating effectively with other departments. 
  • Supporting standard scoping and proposal development appropriate to experience. 
  • Identifying scope risks, delivery efficiencies and client needs and feeding these back internally. 
  • Contributing to practice improvement through working groups, research, tooling, automation and methodology development. 
  • Sharing knowledge through internal events, knowledge-base content, demonstrations and write ups. 
  • Supporting peers and, as experience develops, buddying or informally mentoring junior colleagues. 

Essential Qualities 

The successful candidate will normally meet the essential criteria below. 

  • You will be UK-based 
  • Current UK Security Check (SC) clearance, or eligibility and willingness to obtain and maintain SC clearance. 
  • Hands-on penetration testing experience, including the ability to independently deliver standard assignments, manage testing activity responsibly and produce clear, accurate and client-ready reports. 
  • A current CREST Registered Penetration Tester (CRT), Cyber Scheme Team Member (CSTM) recognised practitioner-level technical qualification. 
  • Current CHECK Team Member status. 
  • UK Cyber Security Council Practitioner professional registration, or clear evidence of working towards registration and the ability to achieve it within an agreed timeframe. 
  • Practical capability to undertake standard web application and API testing and infrastructure testing independently.
  • Strong written and verbal communication skills, including the ability to explain technical findings, business risk and proportionate remediation clearly to clients and colleagues. 
  • A professional and collaborative approach to client delivery, including effective workload management, scope awareness, timely escalation of risks or blockers and a constructive response to quality assurance feedback.

Desirable Qualities

  • Experience delivering CHECK or other public-sector security testing engagements. 
  • Broader practical experience in one or more adjacent service areas, such as mobile application testing, cloud security, Microsoft 365 or Entra ID reviews, desktop or thick-client testing, secure configuration reviews, wireless testing or source code review. 
  • Additional specialist or platform qualifications, such as Burp Suite Certified Practitioner, CRTO, CRTP, CRTE, CARTP, relevant Hack The Box certifications or cloud-specific security certifications. 
  • IASME assessor qualifications or experience delivering Cyber Essentials, Cyber Essentials Plus or related assurance services. 
  • Experience contributing to scoping and proposal development, internal knowledge sharing, mentoring, methodology improvement, research, tooling or automation. 

Remuneration and benefits 

  • Salary £40 - £55k negotiable depending on skills, experience, and qualifications 
  • Matched company pension up to 5% 
  • Private healthcare 
  • 25 days annual holiday, increasing to 30 days after 3 years 
  • Membership to the Employee Assistance Programme (EAP) 
  • 3x salary death in service 
  • Excellent working conditions and environment.